| Attribute | Detail |
|---|---|
| Origin | China (state-aligned) |
| Active since | At least 2012 |
| Motivation | Cyber espionage, intelligence collection, long-term access |
| MITRE ATT&CK ID | G0129 |
| Notable aliases | Earth Preta, Hive0154, Bronze President, Stately Taurus, RedDelta, Camaro Dragon, HoneyMyte, PKPLUG, Twill Typhoon, TA416 |
| Signature malware | PlugX, TONESHELL, PUBLOAD, LOTUSLITE, SnakeDisk, ZOHOMURK, MINIRECON |
| Primary regions | Southeast Asia, East Asia, Europe, Middle East, North America |
| Signature tradecraft | DLL sideloading via signed binaries, spearphishing with geopolitical lures, abuse of legitimate cloud services |
Dark Web Profile: Mustang Panda
Mustang Panda is one of the most persistent China-nexus cyber espionage groups operating today. Active since at least 2012, the group has targeted government agencies, military bodies, diplomatic missions, NGOs, and religious organizations across Southeast Asia, Europe, the Middle East, and the United States, consistently aligning its operations with Beijing’s strategic and foreign policy priorities.
It is best known for its long-running use of PlugX, a modular remote access trojan (RAT), but has steadily expanded its toolkit in response to law enforcement action and growing defender awareness. In June 2026, researchers documented two concurrent Mustang Panda campaigns against India’s government and hydropower sectors deploying an entirely new implant set, a reminder that this is a threat actor that never stops retooling.
Who Is Mustang Panda?
Mustang Panda (MITRE ATT&CK: G0129) is a Chinese state-linked cyber espionage actor operational since at least 2012. The group was first publicly identified in 2017 after activity targeting a US-based think tank, and has since been attributed by the US Department of Justice, the FBI, and multiple intelligence vendors to the People’s Republic of China. Its operations are espionage-driven rather than financially motivated, focused on long-term access and intelligence collection against high-value political, governmental, and strategic targets.

Threat actor card of Mustang Panda
The group is tracked under a wide range of names across the security industry, reflecting how many vendors have independently clustered its activity over the years. Aliases include Earth Preta, Hive0154, Bronze President, Stately Taurus, RedDelta, Camaro Dragon, HoneyMyte, PKPLUG, Twill Typhoon, TA416, BASIN, CeranaKeeper, Fireant, and Polaris.
Not every researcher treats these labels as perfectly synonymous, and some track distinct subclusters within the broader entity, but they all describe the same long-running China-aligned espionage operation.
One of Mustang Panda’s defining characteristics is its high operational tempo and its ability to assimilate new tools and tactics rapidly. The group has repeatedly demonstrated that it will absorb the loss of infrastructure or the public burning of a malware family and return within months with a retooled arsenal.
This resilience, combined with a consistent focus on targets that map to Beijing’s interests, has made Mustang Panda one of the most closely tracked APTs in the world.
2025 PlugX Disruption
In January 2025, the US Department of Justice and FBI, working with international partners, disclosed a court-authorized operation that deleted PlugX from thousands of infected computers in the United States, targeting a variant of the malware the group had used for years.
The disruption was significant, but it did not slow the group for long. By later in 2025 and into 2026, Mustang Panda had retooled around newer families including the LOTUSLITE backdoor and the SnakeDisk USB worm, and resumed operations against government and policy targets. This pattern, losing a signature tool and re-emerging with fresh capability, is central to understanding the threat.
What Are Mustang Panda’s Targets?
Mustang Panda’s victimology tracks closely with China’s geopolitical priorities. Over more than a decade, the group has pursued government bodies, military and defense entities, diplomatic missions, think tanks, NGOs, telecommunications providers, and religious and minority-focused organizations.
Reporting has repeatedly placed the group’s operations against the Vatican, European diplomatic bodies during the invasion of Ukraine, attendees of regional summits such as the ASEAN-Australia Summit, and government targets across Mongolia, Taiwan, Hong Kong, Tibet, Myanmar, Thailand, Vietnam, the Philippines, and beyond.
In March 2026, following the outbreak of the Iran war, the group extended operations to diplomatic and government entities across the Middle East, a region it had not targeted on a regular basis before.

Mustang Panda’s documented targeting footprint: confirmed 2025-2026 campaign countries (marked) against the broader footprint reported since 2012 (shaded). Reach is global and not limited to the countries shown.
Geographically, long-term monitoring shows a heavy concentration on the Asia-Pacific region, alongside sustained activity across Europe, Africa (including Ethiopia, South Africa, and South Sudan), and North America. Recent campaigns show the group broadening its reach into new sectors and geographies while keeping the same espionage objective.

Recent targeting summary infographic
The consistent thread is that victims are selected for their intelligence value to the Chinese state. Lures are tailored to the target, drawing on real international conferences, bilateral engagements, and region-specific political events to maximize the chance a recipient will open a malicious document.
How Does Mustang Panda Operate?
Mustang Panda pairs simple, well-tested delivery techniques with a steadily evolving malware arsenal. The group’s tradecraft centers on spearphishing, DLL sideloading through legitimate signed executables, and the abuse of trusted cloud services to hide command-and-control (C2) traffic inside ordinary network activity.
Arsenal and Tooling
- PlugX: A long-running modular remote access trojan (RAT) used for more than a decade. Although parts of its infrastructure have been disrupted, the malware family remains active and continues to appear in recent campaigns.
- TONESHELL: A backdoor family that has evolved through multiple versions, adding improved evasion, proxy support, and more resilient communication methods.
- PUBLOAD / PUBSHELL: Loader and downloader families that share architectural similarities with TONESHELL and have been linked to the same operational ecosystem.
- LOTUSLITE: A backdoor that has appeared in campaigns targeting government institutions, financial organizations, and diplomatic entities. Its delivery methods have evolved from CHM files to JavaScript loaders and DLL sideloading.
- SnakeDisk: A USB-propagated worm designed to target isolated or segmented environments by deploying a secondary backdoor on selected systems.
- COOLCLIENT: A secondary backdoor observed alongside PlugX in campaigns across multiple countries.
- ZOHOMURK and MINIRECON: Two more recent malware families that demonstrate the group’s continued investment in stealthier persistence and cloud-based command-and-control techniques.
The June 2026 India Campaigns: SHARDLOADER, MINIRECON, and ZOHOMURK
In June 2026, two documented concurrent campaigns against Indian government entities were detected. One campaign was themed around a proposal for hydropower cooperation; the other around a memorandum of understanding between Indian and Taiwanese institutions. Both were delivered as ZIP archives, distributed via spearphishing, in which the malicious DLL was marked with the hidden attribute, a technique long associated with the group.
Both campaigns opened the same way: a previously undocumented loader tracked as SHARDLOADER, delivered as a malicious DLL and sideloaded through a legitimate, digitally signed executable. In the hydropower campaign, the host was a Solid PDF Creator component invoked through the malicious export GetSPApp. From there, the two campaigns diverge:
- Campaign I (hydropower) decrypts and launches MINIRECON, a variant of the Toneshell8 implant. It retains Toneshell fingerprints such as PEB-walking to locate kernel32.dll and the family’s 13131313 API-hashing multiplier, but upgrades C2 to a WebSocket connection over HTTPS using the native WinHTTP API, disabling certificate validation to allow self-signed certificates, and includes a proxy fallback mechanism to blend into enterprise networks. Acronis observed the operator conducting live reconnaissance on infected hosts and attempting to disrupt analysis after detecting a sandbox.
- Campaign II (MOU / Taiwan) deploys ZOHOMURK, a novel implant that abuses Zoho WorkDrive, a legitimate cloud storage platform widely used in the Indian government sector, for command-and-control, data exfiltration, and remote task execution. ZOHOMURK authenticates to Zoho’s OAuth API using hardcoded credentials, creates per-victim inbox and outbox folders on the operator’s WorkDrive account, and passes commands and stolen data as ordinary-looking cloud API traffic. It supports interactive shell access, file operations, and a self-healing heartbeat that re-registers the victim if the C2 folders are removed.
Researchers attributed the activity to Mustang Panda with high confidence, citing the reused Solid PDF Creator sideloading chain, code overlap with TONESHELL, C2 infrastructure sitting in the same /24 subnet as a Pubload C2 server previously tied by IBM to Hive0154 (Mustang Panda), and a recurring misspelling, RunOnece, carried across multiple implants
Researchers identified active beaconing from multiple compromised Indian government systems, including devices tied to senior administrative personnel, between June 12 and June 22, 2026, and worked with CERT-In on victim notification and remediation.
Common Tradecraft Across Campaigns
Regardless of the specific payload, Mustang Panda’s operational playbook stays consistent:

Common techniques utilized by Mustang Panda
What Are the Mitigation Tactics Against Mustang Panda?
Mustang Panda’s reliance on trusted binaries, legitimate cloud services, and social engineering means defense has to combine endpoint hardening, network visibility, and user awareness. The following measures map directly to the group’s documented tradecraft.
Block and Detect Initial Access
- Treat archives that contain an executable paired with a same-named DLL, particularly a hidden DLL, as high-risk, and inspect them before execution.
- Train high-value staff, especially in government, diplomatic, and critical infrastructure roles, to recognize spearphishing lures themed around conferences, bilateral agreements, and current events.
- Strip or quarantine hidden-attribute files delivered inside ZIP archives at the mail gateway.
Counter DLL Sideloading
- Monitor for legitimate signed binaries loading unsigned or unexpected DLLs from user-writable directories such as C:ProgramData, C:UsersPublicDocuments, and %LOCALAPPDATA%.
- Alert on trusted applications (Solid PDF Creator, Microsoft DNX, Citrix components) executing from non-standard paths.
- Watch for executables calling EnumSystemLocalesA shortly after allocating RWX memory, a pattern seen in MINIRECON’s shellcode execution.
Watch Legitimate Cloud Services
- Baseline and monitor for non-browser processes making requests to cloud APIs such as accounts.zoho.com/oauth/v2/token and workdrive.zoho.com, and flag unusual User-Agents like Zoho Client/1.0, Zoho API C-Client/1.0, and Zoho-C-Uploader/2.0.
- Extend the same scrutiny to Google Drive, Box, and dynamic DNS traffic originating from non-browser executables, since the group rotates through legitimate services.
- Inspect for WebSocket-over-HTTPS beaconing to newly registered domains with self-signed certificates, consistent with MINIRECON.
Harden Persistence and Recovery
- Alert on new Run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with suspicious value names (for example MicrosoftEdgeUpdateBrokerTask, MediumNetMonIt, ZohoUsingUpdataAnyssAll_RunOnece).
- Monitor for scheduled tasks with short repetition intervals pointing to executables in user-writable directories (for example the SolidPDFPcl2Bmp task with a five-minute trigger).
- Hunt for the recurring RunOnece typo across registry, mutex, and file artifacts, a distinctive fingerprint of this actor.
Apply Threat Intelligence
- Ingest known Mustang Panda C2 domains, IPs, hashes, and mutex strings into detection and blocking pipelines, and enrich indicators with reputation, WHOIS, and passive DNS context.
- Track the group’s infrastructure reuse patterns, such as recurring hosting providers and autonomous systems, to anticipate new campaigns from shared network blocks.
- Coordinate with national CERTs where compromise is suspected, given the group’s focus on government and critical infrastructure.
What Are the MITRE ATT&CK TTPs of Mustang Panda?
The table below summarizes techniques associated with Mustang Panda across its recent campaigns. It is representative rather than exhaustive, given the breadth of the group’s tooling.
| Tactic | Technique ID | Technique Name |
|---|---|---|
| Reconnaissance | T1592 | Gather Victim Host Information |
| Resource Development | T1583.001 | Acquire Infrastructure: Domains |
| Resource Development | T1587.001 | Develop Capabilities: Malware |
| Resource Development | T1585.002 | Establish Accounts: Email Accounts |
| Initial Access | T1566.001 | Phishing: Spearphishing Attachment |
| Initial Access | T1566.002 | Phishing: Spearphishing Link |
| Initial Access | T1091 | Replication Through Removable Media |
| Execution | T1204.002 | User Execution: Malicious File |
| Execution | T1059.007 | Command and Scripting Interpreter: JavaScript |
| Execution | T1106 | Native API |
| Persistence | T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys |
| Persistence | T1053.005 | Scheduled Task/Job: Scheduled Task |
| Defense Evasion | T1574.002 | Hijack Execution Flow: DLL Side-Loading |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| Defense Evasion | T1564.001 | Hide Artifacts: Hidden Files and Directories |
| Defense Evasion | T1622 | Debugger Evasion |
| Defense Evasion | T1036.005 | Masquerading: Match Legitimate Name or Location |
| Discovery | T1082 | System Information Discovery |
| Discovery | T1083 | File and Directory Discovery |
| Command and Control | T1071.001 | Application Layer Protocol: Web Protocols |
| Command and Control | T1102.002 | Web Service: Bidirectional Communication |
| Command and Control | T1573 | Encrypted Channel |
| Command and Control | T1105 | Ingress Tool Transfer |
| Exfiltration | T1567.002 | Exfiltration Over Web Service: Cloud Storage |
| Collection | T1005 | Data from Local System |
What Are the Indicators of Compromise (IOCs) for Mustang Panda?
The indicators below are drawn primarily from Acronis TRU’s June 2026 India campaign research and its April 2026 LOTUSLITE research. Mustang Panda rotates infrastructure aggressively, so these should be treated as historical markers and enrichment pivots rather than a complete or current blocklist.
C2 Domains
- couldinstallup[.]com (MINIRECON WebSocket C2)
- editor[.]gleeze[.]com (LOTUSLITE v1.1 C2)
- www[.]cosmosmusic[.]com (LOTUSLITE delivery)
IP Addresses
- 188.208.141.177 (MINIRECON C2, Leapswitch Networks, AS132335)
- 188.208.141.196 (Pubload C2 previously tied to Hive0154, same /24 subnet)
- 172.81.60.97 (original LOTUSLITE C2, Dynu Systems, AS398019)
SHA-256 Hashes (June 2026 India campaigns)
- cd9397797216fd4c08df324937509124e57258328c8e4c6d795c6a2cd25b69b0 (Hydropower Cooperation Project Proposal.zip)
- fcf4efa82d477c924d42cc6b71aa672ab2381ca256769925ae34dabe2e77e025 (Hydropower Cooperation Project Proposal.exe)
- ebd533de7ca16daa70093b0b1084fb6136b6ba091d6ee0e4199762581e1b2e5a (SolidPDFCreator.dll)
- 390148f5157c0f6b337ff19d162c3c2ee3e6d782fdfbe11fb1e411c0684fd33b (test.doc)
- 5f22ec5c14dfd47c92850a5fb3bd8e3754d538b8021b6238238e4020336cfb5c (ctxmui.dll, ZOHOMURK Variant 1)
- f53fd0626404a129dcddb8ee7589387dd7bda7999814e0df46c670af6b3da5f5 (MOU USI-INDSR TAIWAN.zip)
- a43084f5af861f44c75c5273c779cb26d506cab6b51c33746626da504148a4ec (SolidPDFCreator.dll)
- f2bed071676feb831ed460489643fd57f6c6c1e0d024a1ea447820276fb13828 (ctxmui.dll, ZOHOMURK Variant 2)
Registry Run Key Value Names
- MicrosoftEdgeUpdateBrokerTask (ZOHOMURK v2)
- ZohoUsingUpdataAnyssAll_RunOnece (ZOHOMURK v1)
- MediumNetMonIt (SHARDLOADER v1.0)
Scheduled Task
- SolidPDFPcl2Bmp (trigger Pcl2BmpDailyTrigger, five-minute repetition)
Mutex / Named Event Objects
- LocalMS_Edge_Update_Task_Service_Sync (ZOHOMURK v2)
- ZohoUsingUpdataAnyssAll_event (ZOHOMURK v1)
- uydgcfteionxcfd (SHARDLOADER v1.0)
- mdseccoUkFuiCkTrump (LOTUSLITE)
File System Artifacts
- C:ProgramDataIDMlogs (SHARDLOADER staging, hidden)
- C:UsersPublicDocumentspcl2bmp.exe + ctxmui.dll (ZOHOMURK execution)
- %LOCALAPPDATA%MicrosoftVaultCache (ZOHOMURK v2 persistence)
- readata.dat (ZOHOMURK command staging)
Suspicious User-Agents (non-browser processes)
- Zoho Client/1.0
- Zoho API Client/1.0
- Zoho API C-Client/1.0
- Zoho-C-Uploader/2.0
- IPFetcher/1.0
A live, enriched, and continuously updated set of Mustang Panda indicators is available through the SOCRadar platform.

SOCRadar Platform, Threat Actor Details
How SOCRadar Modules Support Ongoing Monitoring and Assessment
Because Mustang Panda rotates infrastructure constantly and cycles through malware families between campaigns, point-in-time blocking is not enough. SOCRadar supports detection and response across the group’s full footprint:
- Cyber Threat Intelligence maintains a detailed threat actor profile for Mustang Panda and its many aliases, mapping known campaigns, IOCs, infrastructure clusters, and TTP evolution over time, so teams can tell whether a new indicator represents a fresh campaign or infrastructure reuse.
- IOC Radar lets analysts search and pivot on indicators extracted from Mustang Panda campaigns, including C2 domains such as couldinstallup[.]com and editor[.]gleeze[.]com, PlugX, TONESHELL, LOTUSLITE, and ZOHOMURK hashes, and mutex strings documented across variants, with enrichment for reputation, WHOIS, and passive DNS.
- Attack Surface Management identifies internet-facing assets that may present initial access opportunities consistent with the group’s targeting, an important input given the group’s use of spearphishing lures built on publicly visible organizational context.
- Brand Protection monitors for spearphishing and impersonation infrastructure spoofing your organization or your partners, including domain registrations and typosquats consistent with Mustang Panda’s delivery patterns.
Conclusion
Mustang Panda is a durable, well-resourced China-aligned espionage actor that has stayed at the front of the threat landscape for more than a decade by continuously refreshing its tools while keeping its core playbook intact.
The consistent through-line is intent. Whether the target is an Indian hydropower agency, a South Korean policy circle, a US think tank, or a Thai government office, Mustang Panda selects victims for their intelligence value to the Chinese state and invests in per-stage evasion to keep long-term access.

